← Back to Trust Center

Coordinated Vulnerability Disclosure Policy

0. Preamble

In this Policy, "xTool" means Makeblock Co., Ltd., which owns the xTool brand and is the "manufacturer" of xTool-branded products within the meaning of Article 3(13) of Regulation (EU) 2024/2847 (Cyber Resilience Act), together with its subsidiaries and affiliates that develop, manufacture, distribute or operate xTool-branded products and services (collectively, "xTool"). The commitments in this Policy, including the Safe Harbor in Section 4, are made on behalf of and apply to all such entities.

1. Our Commitments

For any vulnerability report submitted in accordance with this Policy, xTool commits to:

  • Acknowledge receipt within 1 business day;

  • Complete initial triage and validation within 5 business days;

  • Remediate or mitigate within the timelines in Section 6 (Response SLA), which distinguish cloud/web services from device firmware;

  • Agree on a disclosure timeline with the researcher;

  • Provide acknowledgment and rewards for eligible valid reports within the scope of this Policy;

  • Not pursue legal action against researchers beyond the scope of this Policy (see Section 4 Safe Harbor).

2. Scope

2.1 In-Scope Assets

The following assets are within scope:

  • xTool official websites: *.xtool.com, *.atomm.com, *.customthings.com (Except for third-party SaaS service providers using the xtool official domain)

  • xTool official mobile apps: xTool Studio App (iOS / Android) and OTA update channels

  • xTool official desktop software: xTool Studio and officially released firmware images (excluding user-modified variants)

  • xTool hardware products: CO2 Laser, Fiber Laser, UV Laser,Diode Laser, Laser Welder / CNC Cutter, DTF Printer

  • xTool officially operated model library / resource library platforms (Atomm Community, the platform infrastructure of the model/asset library) — scope limited to platform-level security (authentication, authorization bypass, injection, etc.); does not cover copyright/compliance of user-uploaded design files themselves

  • xTool AI services: AI design assistance, AI composition, smart camera recognition APIs and inference endpoints — in-scope issues are those with a security impact (e.g., prompt injection leading to unauthorized data access or privilege escalation); output-quality-only issues are not considered vulnerabilities

2.2 Out-of-Scope Assets

The following are out of scope:

  • Third-party hosted or operated underlying infrastructure (Cloudflare, AWS, GitHub, Aliyun, etc.) — please report via the respective provider's VDP

  • Websites or systems independently operated by xTool affiliates, agents, or distributors (e.g., regional reseller sites on independent domains)

  • Third-party plugins, mods, or modified firmware not released by xTool; issues specific to jailbroken/rooted devices

  • User-generated content (UGC) on xTool forums/model library at the content layer (e.g., copyright infringement, obscene material, violence) — please report via our official channel; however, security vulnerabilities in the UGC hosting system (e.g., XSS, upload-triggered RCE) remain within §2.1 scope

Third-party hardware compatible with xTool ecosystem but not xTool-branded (e.g., third-party laser tubes)

Internal-only systems with no public network exposure, and test environments — except publicly accessible test environments lacking access control or exposing production data/credentials, which are in scope

Third-party platforms integrated with xTool services (e.g., Shopify, payment providers): vulnerabilities in the platform itself are out of scope, but xTool will forward your report to the vendor and, where the vendor confirms its value, advocate for a reward issued by that vendor. Vulnerabilities caused by xTool's own configuration or integration (e.g., misconfigured permissions, leaked keys, missing callback validation) are in scope and rewarded normally.

2.3 Out-of-Scope Vulnerability Categories

The following categories are generally not considered security vulnerabilities, and we reserve the right not to address them:

  • Missing HTTP security headers (CSP, HSTS) without demonstrable exploitation

  • SPF / DKIM / DMARC configuration issues alone

  • Self-signed or weak-cipher certificate warnings

  • Issues requiring social engineering, physical access, or unusual victim actions

  • Low-risk CSRF (public information, non-sensitive actions)

  • Purely theoretical reports without a proof-of-concept

  • Known third-party component vulnerabilities that have been publicly disclosed for 30 days or more (per CVE publication date; if upstream has released a patch but our SBOM entry is not yet synchronized, it falls under internal defect management, see §3.4)

  • Rate limiting or user enumeration (unless bypassing critical business logic)

  • Issues specific to outdated browsers or mobile OS versions

3. How to Submit a Vulnerability Report

3.1 Submission Channels

Link:https://support.xtool.com/trust-center/

3.2 Required Content

To help us triage and respond quickly, please include the following:

  • Vulnerability title and category (e.g., SSRF, RCE, IDOR)

  • Affected asset (URL, product model, firmware version, app version)

  • Detailed reproduction steps and proof-of-concept (screenshots, commands, video)

  • Impact and exploitation complexity assessment

  • Remediation suggestions (optional)

  • Account, IP, and testing window used (to help us correlate logs)

  • Contact information and preferred attribution

3.3 Language

We accept reports in Chinese or English.

3.4 Third-Party Component 0-Day and Software Supply-Chain Vulnerabilities

If you find a vulnerability in a third-party open-source or commercial component used in xTool products (e.g., OpenSSL, Linux kernel, RTOS, open-source web frameworks, commercial cloud SDKs) that has not been publicly disclosed upstream, please submit through the following path so that we can coordinate upstream and downstream remediation:

  • Please also include: upstream vendor information, whether upstream has been notified, whether a CVE has been reserved, and the suggested coordinated disclosure date

  • xTool assumes upstream coordination responsibility: PSIRT coordinates with the upstream / CERT/CC / MITRE, pushes downstream patches, and maintains the SBOM entry; researcher's recognition and reward eligibility under this Policy remains intact

  • For third-party vulnerabilities publicly disclosed for more than 30 days, rewards generally do not apply (see §2.3), but patch verification and compatibility feedback are welcome

4. Legal Safe Harbor

4.1 Safe Harbor Commitment

For security research activities conducted in good faith and in compliance with this Policy, xTool commits to:

  • Consider such activities as authorized security research under xTool's authorization;

  • Not initiate civil litigation or support criminal charges against the researcher for such activities;

  • Not request law enforcement or cybersecurity authorities to open investigations for such activities;

  • If a third party brings claims arising from research conducted under this Policy, we will actively assist in clarifying that such activities were authorized;

  • Not provide vulnerability details reported by researchers to any civil or criminal proceedings against such researchers, except to the extent xTool is compelled to do so by law, court order, subpoena, or other mandatory legal process.

4.2 Laws Covered by Safe Harbor

For research conducted within the authorized scope of this Policy, xTool makes the following unilateral, legally binding commitments (to the extent legally assignable to xTool as victim or reporting party):

  • PRC Criminal Law Article 285 Paragraph 2 (Illegally Obtaining Data from or Illegally Controlling a Computer Information System — the offense most commonly triggered in IoT vulnerability research; Article 285 Paragraph 1 "Illegal Intrusion into Computer Information Systems" only applies to systems in the fields of state affairs, national defense, or cutting-edge science/technology and is generally inapplicable to xTool consumer IoT products), Article 286 (Disruption of Computer Information Systems), and Article 287-2 (Aiding Cybercrime): xTool commits not to proactively report to police/prosecutors, not to file criminal complaints, and not to seek case initiation; however, these are public-action offenses and xTool's commitment cannot bar prosecution initiated ex officio by authorities

  • PRC Cybersecurity Law, Data Security Law, PIPL, and MIIT Order No. 66: xTool commits not to report the researcher's activities to cyberspace/MIIT/public security authorities and acknowledges that access within this Policy constitutes "authorized access"

  • U.S. Computer Fraud and Abuse Act (18 U.S.C. §1030): deemed authorized access, no civil action, no support for criminal prosecution (federal prosecution authority rests with DOJ; xTool will not assist but cannot block)

  • U.S. DMCA anti-circumvention provisions (§1201): xTool will not assert §1201 claims against good-faith security research

  • U.S. state computer crime, data breach notification, and consumer protection laws: no complaint to state AGs, no law enforcement referral for in-scope research

  • EU GDPR: security research conducted in compliance with this Policy is treated as part of xTool's regular testing, assessing and evaluating of security measures under Article 32(1)(d), performed under xTool's authorization; researchers must strictly observe the minimum-necessary and no-retention conditions in Sections 4.3(6)–(7) and the data minimization principle (Art. 5(1)(c)).

  • EU Member State laws transposing Directive 2013/40/EU on attacks against information systems: no criminal complaint by xTool; public-action limitations apply as with PRC criminal law

  • UK Computer Misuse Act 1990 (Sections 1, 2, 3, 3ZA): deemed authorized access, no civil action by xTool, no referral to the National Crime Agency or local police; however, several CMA 1990 offences are public-action (either-way or indictable-only) and where the CPS initiates prosecution ex officio, xTool's commitment cannot bar criminal prosecution — public-action limitations apply as with PRC Criminal Law Articles 285–287-2

  • Any EULA provisions of xTool products and services prohibiting security testing (contractually waived within the scope of this Policy)

NOTE: The legal commitments in this section are effective in the following scope: (1) civil redress; (2) contractual remedies; (3) proactive reporting; (4) disclosure assistance as a party to civil/criminal proceedings. For public-action cases and ex-officio enforcement by authorities, xTool commits not to support charges but has no power to prevent initiation.

4.3 Safe Harbor Conditions

A researcher may benefit from the Safe Harbor only when all of the following conditions are satisfied:

  • (1) Good faith — research is solely for identifying and reporting vulnerabilities, without malicious intent;

  • (2) Scope compliance — only test assets listed in Section 2.1 and never test out-of-scope assets in Section 2.2 ;inadvertent, good-faith contact with an out-of-scope asset that is immediately ceased and disclosed in the report (per Section 5.3) does not by itself void the Safe Harbor;

  • (3) Rules compliance — observe all prohibited actions in Section 5 (Rules of Engagement);

  • (4) Non-disclosure — do not publicly disclose vulnerability details before xTool discloses or agrees to disclosure(see the embargo rules in Section 8.1);

  • (5) No extortion — do not demand money or benefits from xTool or third parties beyond what this Policy provides, and do not coerce;

  • (6) Minimum necessary — access only the least information needed to demonstrate the vulnerability;

  • (7) No retention — do not download, copy, resell, retain, or transfer user data, source code, or internal documents;

  • (8) Lawful reporting — report via Section 3 channels and cooperate with reasonable follow-up communication from xTool.

4.4 Geographic Applicability

xTool makes no guarantee regarding the extraterritorial effect of laws in any jurisdiction. Researchers must independently assess local law compliance based on their location, physical location while testing, and server location.

4.5 Safe Harbor Exclusions

  • Malicious intent or actual damage (DoS, sabotage, ransomware, extortion);

  • Downloading, exfiltrating, or selling user data or source code;

  • Public disclosure of unpatched vulnerabilities (except under the coordinated disclosure mechanism below);

  • Violations of Section 5 (Rules of Engagement);

  • False, fabricated, or deceptive reports.

5. Rules of Engagement

5.1 Permitted Testing

  • Black-box testing against assets in Section 2.1

  • Testing with your own account (recommended registration pattern: user+sec@domain Gmail/sub-address form, to help us identify in logs)

  • Reverse engineering publicly released xTool firmware to discover vulnerabilities

5.2 Strictly Prohibited Actions

  • Denial of Service (DoS / DDoS) testing

  • Brute-force attacks or large-scale scanning impacting service continuity

  • Social engineering against xTool employees, customer service, or partners

  • Physical intrusion (xTool offices, factories, data centers)

  • Accessing, modifying, or deleting other users' accounts, orders, or files

  • Downloading, retaining, or disseminating user data, order data, or source code

  • Planting backdoors, webshells, or persistence mechanisms in production

  • Publishing weaponizable exploits on public platforms (GitHub, Twitter, PoC repositories)

  • Exploiting vulnerabilities for monetary gain (including cryptocurrency, points, or coupon arbitrage)

  • Testing in violation of applicable data protection laws

  • All tests that may affect normal business functions

5.3 Handling Inadvertent Data Access

If you inadvertently access others' data or internal information during testing, immediately cease access, refrain from downloading or taking screenshots (unless necessary for vulnerability proof with personal information redacted), and explicitly state this in your report.

6. Response SLA

Phase Target Notes
First Acknowledgment Within 1 business day Acknowledge receipt and assign tracking ID
Initial Triage Within 5 business days Provide preliminary validity assessment
Critical Fix — cloud/web/app Within 7 days Data breach, RCE, auth bypass, etc.
High Fix — cloud/web/app Within 15 days Significant confidentiality/integrity impact
Medium Fix — cloud/web/app Within 30 days General functional vulnerabilities
Low Fix — cloud/web/app Within 90 days Limited impact
Critical/High Fix — device firmware Mitigation within 7 days; patched firmware within 90 days Firmware release cycles prevent hotfix-speed patching; server-side or configuration mitigations are deployed first where feasible
Medium/Low Fix — device firmware Next scheduled firmware release, no later than 180 days Bundled into regular OTA releases
Reward Payout Within 30 days of validation Paid upon triage confirmation, not remediation; may extend due to sanctions screening or tax withholding
Disclosure Negotiation Default 90 days May be shortened or extended by mutual agreement

Note: All fix timelines above run from severity confirmation (completion of initial triage), not from the date of submission.

7. Recognition & Reward

7.1 Recognition

xTool will thank valid vulnerability reporters via email. Researchers may choose:

Acknowledgment by real name, pseudonym, or anonymously

Public attribution entails processing of researcher personal information, based on: (a) GDPR Art. 6(1)(a) explicit consent — expressed by the researcher selecting a recognition preference in the report template or by reply confirmation; (b) PRC PIPL Art. 13(1) consent basis. Researchers may withdraw consent at any time via privacy@xtool.com and be removed from the trust center page; withdrawal does not affect the lawfulness of prior processing; (c) anonymous recognition does not involve personal information processing.

7.2 Reward Mechanism

xTool will, at its discretion, grant researchers appropriate rewards in accordance with its internal vulnerability severity rating rules.

Reports with harsh exploitation prerequisites (physical proximity, unusual user interaction, non-default configuration) may be rated lower per actual impact; complete exploit chains and high-quality reports (working PoC, impact analysis, remediation advice) may receive higher rewards.

7.3 Non-Payment Situations

  • Reporter is a current xTool employee, former employee within the past 12 months, or key personnel of direct suppliers

  • Reports that are duplicates, invalid, or out of scope

  • Researcher violates Section 5 (Rules of Engagement)

  • Researcher fails sanctions or AML screening

xTool evaluates reports that have no security risks or determines that they will not be accepted

7.4 Duplicate Reports

The first valid report received (by submission timestamp) is eligible for the full reward

Reports matching the root cause of a confirmed vulnerability that is still being fixed are duplicates: they receive acknowledgment but no reward; for firmware vulnerabilities with long release cycles, a duplicate report demonstrating materially greater impact than the original may receive a supplemental reward at xTool's discretion

A vulnerability that has been patched but remains reproducible on devices not yet updated in a phased rollout is treated as a duplicate

To reduce duplicate effort, xTool maintains a summary list of confirmed-and-pending-fix issues (without technical detail) on the Trust Center

8. Confidentiality & Coordinated Disclosure

8.1 Embargo Period

Researchers owe a confidentiality obligation from the date of submission until the earliest of:

  • A disclosure date mutually agreed between xTool and the researcher;

  • 90 days from the date xTool first pushes a patch to end users (first patch release = embargo start date; for phased rollouts, the date when the first end-user batch can install the patch, not the date development completes);

  • The date of xTool's first public disclosure (including security advisory, CVE release, ENISA EUVD disclosure, etc.);

  • Mandatory regulatory disclosure (e.g., ENISA disclosure under CRA Art 14(1), data subject notification under GDPR Art 34) — embargo is automatically lifted upon such disclosure;

  • 180 days from the submission date (hard cap for the researcher's side) — if xTool has neither remediated nor disclosed by then, the researcher may unilaterally conduct coordinated disclosure after giving xTool at least 7 days' prior notice, without losing recognition eligibility or Safe Harbor under this Policy.This unilateral disclosure right is subject to any mandatory restrictions under the law applicable to the researcher; in particular, researchers subject to PRC law remain bound by Article 9 of MIIT Order No. 66 and may not publish vulnerability details before xTool releases its public risk advisory and remediation measures (see Section 10.1), regardless of this contractual timeline.

The 180-day hard cap above only constrains the contractual confidentiality arrangement between the researcher and xTool. It does not diminish, override, or delay any mandatory disclosure deadlines imposed by regulators, including but not limited to: (1) EU Cyber Resilience Act (Regulation (EU) 2024/2847) Article 14(1) — 24-hour early warning and 72-hour vulnerability notification to ENISA / CSIRT for actively exploited vulnerabilities; (2) EU GDPR Article 33 (72-hour notification to supervisory authority) and Article 34 (timely notification to data subjects) for personal data breaches; (3) PRC MIIT Order No. 66 Article 7(2) — network product providers, upon becoming aware of a security vulnerability in their product, shall report the vulnerability information to the MIIT CSTIS platform (which synchronizes to CNVD and CNNVD) within 2 days; (4) material cybersecurity incident disclosure obligations under applicable securities laws and listing rules; (5) similar mandatory disclosure laws in other jurisdictions. Upon any such mandatory disclosure event, the embargo is automatically lifted per Section 8.1 Item 4; xTool's mandatory disclosure obligations take precedence over any timeline in this Policy, and researchers may not invoke contractual confidentiality against regulatory mandatory disclosure.

8.2 Forms of Coordinated Disclosure

  • It will be disclosed with the security patch version notification or displayed in the official website update log.

  • Regulation-driven mandatory disclosure (e.g., automatic lift of embargo upon ENISA disclosure under CRA)

8.3 Consequences of Premature Disclosure

Unauthorized disclosure of vulnerability details by a researcher shall result in: (1) forfeiture of eligibility for acknowledgment and reward; (2) loss of Safe Harbor protection; (3) xTool reserving the right to pursue legal remedies.

9. Processing of Researcher Personal Information

To fulfill obligations under this Policy, xTool collects and processes the following personal information of researchers: name, contact information (email, phone), nationality, place of residence, social media handles (for acknowledgment), payment account information, and tax residency documentation.

Purposes: vulnerability receipt and handling, acknowledgment, reward disbursement, compliance review (sanctions / AML / tax), and legal obligation fulfillment.

Legal basis (GDPR): (a) performance of contract (Art. 6(1)(b)) — reward payout; (b) legitimate interest (Art. 6(1)(f)) — vulnerability intake and PSIRT process; (c) legal obligation (Art. 6(1)(c)) — tax withholding, sanctions screening, regulatory reporting; (d) consent (Art. 6(1)(a)) — public attribution .

Retention: The original report and related personal information are retained for 10 years (to meet evidentiary needs and CRA support-period requirements across PRC/EU/US); reward payout and tax records are retained for the periods required by applicable accounting and tax laws (accounting vouchers and books: 30 years under the PRC Accounting Archives Management Measures); sanctions screening records are retained for 10 years (OFAC recordkeeping requirement, as amended with effect from March 2025). After expiry, data is automatically anonymized or destroyed.

Researcher rights (DSAR): access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, explanation of automated decisions, and complaint to the supervisory authority. xTool commits to respond within 30 days of receipt (GDPR Art. 12(3)); complex requests may be extended up to an additional 60 days with written justification; requests under PRC PIPL Articles 45-50 are handled accordingly. Please contact our Privacy Team at privacy@xtool.com.

10. Special Warnings

10.1 Specific Notice for PRC Researchers

Under MIIT Order No. 66 (PRC Regulations on the Security Management of Network Product Vulnerabilities), Articles 4 and 9 prohibit any organization or individual engaged in discovering, collecting, or disclosing network-product vulnerabilities from:

  • (1) [Article 4] Exploiting vulnerabilities to engage in activities harmful to cybersecurity, or unlawfully collecting, selling, or publishing network-product vulnerability information;

  • (2) [Article 4] Knowingly providing technical support, advertising, payment settlement, or other assistance to a person using vulnerabilities for cybersecurity-harming activities;

  • (3) [Article 9(1)] Publishing vulnerability details before the network product provider has released its public risk advisory and remediation measures;

  • (4) [Article 9(7)] Providing undisclosed vulnerability information to any overseas organization or individual, other than the provider of the relevant network product. For the avoidance of doubt, reports submitted under this Policy by researchers in Mainland China are received by Makeblock Co., Ltd. as the network product provider and do not fall within this restriction.

Violations are subject to legal liability under Article 14 of MIIT Order No. 66, which invokes Articles 60, 62 and 63 of the PRC Cybersecurity Law and related laws (including rectification orders, warnings, fines of CNY 50,000–500,000, and in serious cases licence revocation and individual penalties for responsible persons).

10.2 Export Control and Sanctions Compliance

Vulnerability-related technical information (including PoC and exploit code) may constitute export-controlled items. Researchers shall not forward reports to restricted parties or jurisdictions

11. Policy Changes & Governing Law

11.1 Amendments

xTool may update this Policy from time to time. Material changes will be announced on Trust Center with at least a 30-day transition period. Continued submission after the change constitutes acceptance of the new version.

11.2 Governing Law and Dispute Resolution

The interpretation of this Policy and its Safe Harbor commitment, and any disputes, shall be governed as follows:

  • If the researcher resides in Mainland China: PRC law (excluding conflict-of-laws rules) applies, with jurisdiction at the courts of competent jurisdiction where Makeblock Co., Ltd. is located (Shenzhen);

  • If the researcher resides in the EU / EEA / UK: the law of that country / Member State applies, with jurisdiction at the competent courts in the researcher's country; for personal-data disputes, the researcher may lodge a complaint with the DPA in their place of residence (ICO for the UK); mandatory provisions of GDPR/UK GDPR and consumer protection law are not excluded or limited by this agreement;

  • If the researcher resides in the U.S.: California law (excluding conflict-of-laws rules) applies, with jurisdiction at the federal and state courts of competent jurisdiction where XTL US INC is registered; this choice of law is without prejudice to any mandatory rights the researcher holds under the law of their state of residence or U.S. federal law, including but not limited to state consumer-protection statutes, state data-breach-notification laws (e.g., California SB-327, CCPA/CPRA, New York SHIELD Act, Massachusetts 201 CMR 17.00, Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA), children's online privacy protection (COPPA, 15 U.S.C. §6501), FTC Act §5 consumer-protection law, and mandatory federal law on sanctions, export control, anti-money-laundering, and taxation; to the extent any provision of this Policy conflicts with such mandatory law, such mandatory law shall prevail;

  • Other jurisdictions: Hong Kong SAR law applies, with disputes referred to arbitration at the Hong Kong International Arbitration Centre (HKIAC) under its then-prevailing rules; seat of arbitration shall be Hong Kong; language of arbitration shall be English.

[Mandatory law reservation] The choice of law in this Section does not affect rights granted to the researcher by mandatory laws of their place of residence (e.g., consumer protection, data protection, labor law). If any provision of this Policy conflicts with such mandatory law, the mandatory law prevails without affecting the validity of other provisions.

11.3 Relationship with Other Agreements

This Policy constitutes mutual agreement only regarding vulnerability research and reporting activities, and does not create any employment, partnership, or agency relationship. It does not affect rights and obligations between the researcher and xTool under other agreements (such as EULAs or Terms of Service); however, Section 4 (Safe Harbor) shall prevail within its scope.

xTool Logo

Contact Us

🇺🇸+1 (833) 588-4887
Service Live Chat

Copyright © 2026 xTool All Rights Reserved.